CVE-2021-40438 (matched: apache http server)

  • Friday, 7th August, 2026
  • 10:07am

A security flaw has been identified in Apache HTTP Server, a widely used web server platform. The issue exists in its mod_proxy feature, which routes incoming visitor requests to the backend server that hosts your website’s content.

A specially crafted request can exploit this vulnerability to trick the proxy into sending the request to a server chosen by the attacker, rather than your intended backend server. This flaw affects all versions of Apache HTTP Server 2.4.48 and earlier.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438

« Back